跳到主要內容

簡易檢索 / 詳目顯示

研究生: 黃顥霆
Huang, Hao Ting
論文名稱: 適用於物聯網之 ASCON 輕量級認證金鑰交換 (AKE) 協定
A Lightweight Authenticated Key Exchange (AKE) Protocol for IoT Using ASCON
指導教授: 左瑞麟
口試委員: 左瑞麟
林詠章
蔡家緯
蔡東佐
劉子源
學位類別: 碩士
Master
系所名稱: 資訊學院 - 資訊安全碩士學位學程
Master Program in Information Security
論文出版年: 2026
畢業學年度: 114
語文別: 英文
論文頁數: 68
中文關鍵詞: 輕量化驗證式金鑰交換內部攻擊物聯網安全
外文關鍵詞: Lightweight AKE, Insider Attacks, IoT Security
相關次數: 點閱:7下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 近期物聯網(IoT)系統中所發生的安全事件,揭露了相關環境下
    因保護機制不足而導致的嚴重隱私風險。儘管已有許多輕量化驗證式金鑰交換(Authenticated Key Exchange, AKE)協定被提出,然而其中部分方案仰賴多使用者或多裝置間共用的秘密資訊,進而可能使具備合法憑證的內部攻擊者發動內部攻擊,並削弱雙向驗證的安全性。為解決上述問題,本文提出一種專為物聯網(IoT)環境設計的輕量化AKE 方案,結合具關聯資料之驗證式加密(Authenticated Encryption with Associated Data, AEAD)原語(如 ASCON)、雜湊函數與 XOR 運算,以確保工作階段金鑰的即時性與機密性。透過 ProVerif 工具進行形式化驗證,結果證實本方案所宣稱之安全性質;效能評估亦顯示,在計算與通訊成本與現有方案(如 LAKE-6SH)相當的情況下,所提方案能有效提升對內部濫用行為的抵禦能力。


    Recent security incidents in smart IoT systems have exposed critical privacy risks stemming from inadequate protection mechanisms in Internet of Things (IoT) environments. Although many lightweight authenticated key exchange (AKE) schemes have been proposed, several rely on shared secrets among multiple users or devices, which can enable insider attacks and
    weaken mutual authentication. To address these issues, this paper proposes a lightweight AKE scheme tailored for smart IoT environments, leveraging authenticated encryption with associated data (AEAD) primitives such as ASCON, along with hash functions and XOR operations, to ensure session key
    freshness and confidentiality. Formal verification using the ProVerif tool validates the claimed security properties, while performance evaluation shows that the proposed scheme achieves improved resistance to insider misuse with
    computational and communication overhead comparable to existing schemes such as LAKE-6SH

    誌謝 i
    摘要 iii
    Abstract iv
    Contents v
    List of Figures vii
    List of Tables viii
    1 Introduction 1
    1.1 Motivation 2
    1.2 Contribution 2
    2 Related Work 4
    2.1 Overview of the LAKE-6SH Protocol 4
    2.2 Security Weaknesses and Technical Gaps in LAKE-6SH 6
    3 System Model 9
    3.1 Network Model 11
    3.2 Threat Model 12
    3.3 Preliminaries 12
    3.4 Problems in Lightweight AKE for IoT Environments 15
    4 Proposed Scheme 17
    4.1 IoT device deployment 17
    4.2 Remote User Registration 18
    4.3 Remote User AKE 21
    4.4 Password and Credential Update 34
    4.5 Access Revocation and Reissue 35
    4.6 Scalable Node Addition 37
    5 Security Analysis 39
    5.1 Formal Security Analysis Using Random Oracle Model 39
    5.2 ProVerif Security Analysis 43
    5.3 Informal Security Analysis 45
    6 Performance Evaluation 49
    7 Conclusions 57
    A. ProVerif Formal Verification Code 59
    Reference 66

    [1] M. Tanveer, G. Abbas, Z. H. Abbas, M. Bilal, A. Mukherjee, and K. S. Kwak, “Lake6sh: Lightweight user authenticated key exchange for 6lowpan-based smart homes,” IEEE Internet of Things Journal, vol. 9, no. 4, pp. 2578–2591, Feb. 2022.
    [2] J. Wei, G. Tian, X. Chen, and W. Susilo, “Lightweight 0-rtt session resumption protocol for constrained devices,” IEEE Transactions on Information Forensics and Security, vol. 19, pp. 3573–3588, 2024.
    [3] Y. Zhang, D. He, P. Vijayakumar, M. Luo, and X. Huang, “Sapfs: An efficient symmetric-key authentication key agreement scheme with perfect forward secrecy for industrial internet of things,” IEEE Internet of Things Journal, vol. 10, no. 11,
    pp. 9716–9726, Jun. 2023.
    [4] G. Yu, Q. Li, H. Mao, A. A. A. El-Latif, and J. J. P. C. Rodrigues, “A multi-scenario authenticated key exchange scheme with forward secrecy for fog-enabled vanets,” IEEE Transactions on Vehicular Technology, 2024.
    [5] Q. Xie, Z. Ding, and B. Hu, “A secure and privacy-preserving three-factor anonymous authentication scheme for wireless sensor networks in internet of things,” Security and Communication Networks, vol. 2021, p. 4799223, Sep. 2021.
    [6] H. Alasmary and M. Tanveer, “Esci-aka: Enabling secure communication in an iotenabled smart home environment using authenticated key agreement framework,” Mathematics, vol. 11, no. 16, p. 3450, Aug. 2023.
    [7] Y. Guo, Y. Guo, P. Xiong, F. Yang, and C. Zhang, “Deeper insight into why authentication schemes in iot environments fail to achieve the desired security,” IEEE Transactions on Information Forensics and Security, vol. 19, pp. 4615–4627, 2024.
    [8] H. Ma, C. Wang, G. Xu, Q. Cao, G. Xu, and L. Duan, “Anonymous authentication protocol based on physical unclonable function and elliptic curve cryptography for smart grid,” IEEE Systems Journal, 2023.
    [9] R. Amin, S. K. H. Islam, G. P. Biswas, M. K. Khan, and N. Kumar, “A robust and anonymous patient monitoring system using wireless medical sensor networks,” Future Generation Computer Systems, vol. 80, pp. 483–495, Mar. 2018.
    [10] M. Shuai, N. Yu, H. Wang, and L. Xiong, “Anonymous authentication scheme for smart home environment with provable security,” Computers & Security, vol. 86, pp. 132–146, Sep. 2019.
    [11] C. Dobraunig, M. Eichlseder, F. Mendel, and M. Schläffer, “Ascon v1.2: Lightweight authenticated encryption and hashing,” Journal of Cryptology, vol. 34, no. 33, 2021.
    [12] A. K. Das, M. Wazid, N. Kumar, A. V. Vasilakos, and J. J. P. C. Rodrigues, “Biometrics-based privacy-preserving user authentication scheme for cloud-based industrial internet of things deployment,” IEEE Internet of Things Journal, vol. 5,
    no. 6, pp. 4900–4913, Dec. 2018.
    [13] M. Wazid, A. K. Das, V. Odelu, N. Kumar, M. Conti, and M. Jo, “Design of secure user authenticated key management protocol for generic iot networks,” IEEE Internet of Things Journal, vol. 5, no. 1, pp. 269–282, Feb. 2018.
    [14] S. Challa et al., “Secure signature-based authenticated key establishment scheme for future iot applications,” IEEE Access, vol. 5, pp. 3028–3043, 2017.
    [15] J. Srinivas, A. K. Das, N. Kumar, and J. J. P. C. Rodrigues, “Tcalas: Temporal credential-based anonymous lightweight authentication scheme for internet of drones environment,” IEEE Transactions on Vehicular Technology, vol. 68, no. 7, pp. 6903–6916, Jul. 2019.
    [16] M. Wazid, A. K. Das, N. Kumar, A. V. Vasilakos, and J. P. C. Rodrigues, “Design and analysis of secure lightweight remote user authentication and key agreement scheme in internet of drones deployment,” IEEE Internet of Things Journal, vol. 6, no. 2, pp. 3572–3584, Apr. 2019.
    [17] Z. Ali, S. A. Chaudhry, M. S. Ramzan, and F. Al-Turjman, “Securing smart city surveillance: A lightweight authentication mechanism for unmanned vehicles,” IEEE Access, vol. 8, pp. 43 711–43 724, 2020.
    [18] Y. Chen, L. López, J.-F. Martínez, and P. Castillejo, “A lightweight privacy protection user authentication and key agreement scheme tailored for the internet of things
    environment: Lightpriauth,” Journal of Sensors, vol. 2018, p. 7574238, 2018.
    [19] B. A. Alzahrani, A. Barnawi, A. Albarakati, A. Irshad, M. A. Khan, and S. A. Chaudhry, “Skia-sh: A symmetric key-based improved lightweight authentication scheme for smart homes,” Wireless Communications and Mobile Computing, vol.
    2022, p. 8669941, Feb. 2022.
    [20] S. Hussain, Y. B. Zikria, G. A. Mallah, C.-M. Chen, M. D. Alshehri, F. Ishmanov, and S. A. Chaudhry, “An improved authentication scheme for digital rights management
    system,” Wireless Communications and Mobile Computing, vol. 2022, p. 1041880, Jan. 2022.
    [21] K. J. Almalki, A. Jabbari, K. Ayinala, S. Sung, B.-Y. Choi, and S. Song, “Elsa: Energy-efficient linear sensor architecture for smart city applications,” IEEE Sensors Journal, vol. 22, no. 7, pp. 7074–7084, 2022.
    [22] H. Alasmary, “Rdaf-iiot: Reliable device-access framework for the industrial internet of things,” Mathematics, vol. 11, no. 12, p. 2710, 2023.
    [23] M. Tanveer, A. Aldosary, S.-U.-D. Khokhar, A. K. Das, S. A. Aldossari, and S. A. Chaudhry, “Paf-iod: Puf-enabled authentication framework for the internet of drones,” IEEE Transactions on Vehicular Technology, vol. 73, no. 7, pp. 9560–9574, 2024.

    無法下載圖示 全文公開日期 2031/08/10
    QR CODE
    :::